FedRAMP 20x is the U.S. government's modernized authorization framework for cloud service providers that sell to federal agencies. It replaces Rev5's document-heavy, point-in-time review with continuous, machine-verifiable validation built on Key Security Indicators (KSIs), and it reorganizes authorization into Certification Classes A through D. The classes descend from the old impact levels without renaming them: Class B is the closest heir of the old Low baseline, Class C of Moderate (the class most enterprise SaaS ultimately needs, and the one Anecdotes holds), while Class A is a new entry tier for mature programs joining the federal market and Class D (High) is still being developed in the program's Phase 4.
On this page
Certification Classes A–D
What the KSI validation model replaces
Who can begin without an agency sponsor
Rev5 vs. FedRAMP 20x at a glance
How Anecdotes reads FedRAMP 20x
Frequently asked questions
Key takeaways
Certification Classes A–D
The most visible change in FedRAMP 20x is how it labels what you are being authorized for. In place of the older Low, Moderate, and High impact levels, 20x organizes authorization into Certification Classes. The classes descend from those levels rather than renaming them, and FedRAMP itself warns against reading them as one-for-one replacements: a class signals the level of assurance provided, not an old impact level with a new name. Three of the four classes are defined and available today; the fourth is still being built. The definitions below come from the FedRAMP program's own FedRAMP 20x page.
Class A
Class A certifications are for cloud services with mature security and compliance programs that are looking to enter the federal marketplace. That is the provider side. On the agency side, FedRAMP treats Class A as adequate for pilots and for extremely low or negligible-risk use cases, such as processing public information. Class A is 20x's new light entry tier: it maps to no Low, Moderate, or High level, and it is not the old "FedRAMP Ready" designation either. It asks for a small amount of information in advance, and FedRAMP notes that many services with world-class security programs choose to invest only in a Class A or B certification.
Class B (Low)
Class B certifications are for cloud services that provide fairly common small-scale or light-use services, where an entire agency is unlikely to use the service for important work. Class B is the closest heir of the old Low baseline, a lineage rather than a rename.
{{ banner-image }}
Class C (Moderate)
Class C certifications are for cloud services that provide common enterprise services likely to be used in systems across an entire agency, or that provide important government services. Class C is the closest heir of the old Moderate baseline, and it is the class most enterprise SaaS selling to the government ultimately needs. Ultimately is the operative word: the classes are designed to be climbed, and entering at Class A or B and moving up is the normal path unless an agency contract already requires Class C. It is also the class Anecdotes holds, as the first agentic GRC platform to earn FedRAMP 20x Moderate (Class C), on its own platform, and it got there by the same climb, landing at Low first, then Moderate.
Class D (High)
Class D is the framework's high-impact tier, intended for the most sensitive federal systems. Its rules are not final. The FedRAMP program states that Class D "will be developed during FedRAMP 20x Phase 4," with a pilot the program estimates for late 2026 into early 2027 (FY27 Q1 to Q2), and FedRAMP is explicit that its future dates are estimates. If you are researching a high-impact system today, treat Class D as forthcoming rather than something you can pursue right now.
As of this writing, the full rules for FedRAMP 20x Certification are finalized for Classes A, B, and C, while Class D is still in development. Where the program is still defining a class, this guide says so rather than guessing; check the FedRAMP 20x page for the current status.
What the KSI validation model replaces
To see what 20x changes, start with what it replaces. Under Rev5, a provider wrote long control narratives (System Security Plans that routinely ran to hundreds of pages) and proved them through a manual assessment, typically once a year. The document was the deliverable, and the proof behind it was a point-in-time snapshot: true on assessment day, unverified for the eleven months after.
Key Security Indicators (KSIs) are how 20x moves off that model. A KSI is a discrete, testable security requirement stated as a measurable outcome rather than a prescriptive process. Instead of a paragraph describing your approach to multi-factor authentication, a KSI states the outcome (for example, phishing-resistant MFA is enforced) in a form that can be checked against machine-readable evidence. KSIs are grouped into ten themes, such as identity and access management and cloud-native architecture; each indicator carries a normative level (a "must" or a "should") and pass/fail criteria, with evidence mapped directly to it.
The shift is structural:
- From document-based to requirement-level. Proof attaches to a specific requirement.
- From point-in-time to continuous. Because the check runs against current evidence, status reflects where you stand now.
- From human-read to machine-verifiable. A KSI and its evidence can be produced and validated automatically, so a reviewer can query proof instead of re-reading prose.
This guide explains what KSIs are and why they matter. The specific indicators, theme by theme, are their own reference: see our FedRAMP 20x KSI checklist for the requirement-by-requirement list.
Who can begin without an agency sponsor
Under the older model, a cloud service provider generally could not begin a FedRAMP authorization without an agency sponsor: a federal agency willing to champion the review. For a provider without an existing federal relationship, that created a chicken-and-egg problem. You needed federal customers to get authorized, and authorization to win federal customers.
FedRAMP 20x introduced a path that does not require an agency sponsor to begin. The program reports that authorization without an agency sponsor "opened the door to offerings such as GRC tools," which went on to become the largest submission category in its pilots. In plain terms, the path lets in horizontal providers, the kind of tools used across many agencies rather than owned by one, that previously struggled to line up a single sponsoring agency.
This doesn’t remove agencies from the picture: agencies still authorize and rely on these services. What changed is the starting line. A provider can pursue 20x certification and reach the FedRAMP Marketplace on the strength of its automated validation package, instead of waiting for a sponsor before it can even begin. You can read the program's own account on the FedRAMP 20x page.
Rev5 vs. FedRAMP 20x at a glance
If you are placing 20x against the Rev5 process you already know, three differences orient the rest:
{{travel-table-11="/guides-comp"}}
Two dates anchor the wind-down: the 2026 Consolidated Rules have applied to new work since July 4, 2026, and no new Rev5 Certifications will be issued after June 11, 2027. For the full Rev5-to-20x differences and the migration timeline, see our post on the FedRAMP 20x transition; for the certification process under the new rules, see our guide on how to get FedRAMP 20x certified.
How Anecdotes reads FedRAMP 20x
Most explainers stop at "20x is faster and automated." But it’s actually a fundamental shift in structure FedRAMP 20x moves authorization from document-based, point-in-time attestation to requirement-level, continuously evidenced compliance, where proof is mapped requirement by requirement and can be checked by a machine. That is the opposite of blunt cross-framework percentage-mapping, the kind that claims one framework "covers 80%" of another without showing which requirement is actually met.
For a platform built to monitor controls continuously on trusted evidence, 20x is not a new hurdle; it is validation of a model the platform already runs. The evidence a team already gathers for ISO 27001, SOC 2, and internal risk work can support 20x KSIs through the same pipeline, without a second collection effort, and one caveat stays visible the whole way: a mapping shows a relationship, not a finished control, so evidence that satisfies an ISO 27001 requirement still has to clear the specific bar a KSI sets. And because the authorization package is machine-readable, agencies and FedRAMP-recognized assessors (the role formerly called a 3PAO) can pull current KSI status and the evidence beneath it directly, rather than waiting on a static document assembled by hand.
Anecdotes did not build this just for customers. It ran the model on itself and holds a FedRAMP 20x Moderate (Class C) certification, earned on its own platform, as one of 13 participants accepted into the program's Phase 2 Cohort 2. The continuous, evidence-based proof 20x now asks for is exactly how the platform was designed. To see how that works in practice, see how Anecdotes automates FedRAMP 20x.
Frequently asked questions
What is FedRAMP 20x?
FedRAMP 20x is the modernized version of FedRAMP, the U.S. government's framework for authorizing the cloud services federal agencies use. Instead of document-heavy review repeated once a year, it validates discrete Key Security Indicators (KSIs) continuously against machine-readable evidence.
What does "20x" mean in FedRAMP 20x?
"20x" is the program's name for this modernized generation of FedRAMP, a signal of the step-change away from the older, documentation-heavy process. It names the whole automation-first framework, not a literal 20-fold measurement.
What are the FedRAMP 20x certification classes?
FedRAMP 20x defines four Certification Classes. Class A is an entry tier for providers with mature security programs, with no counterpart among the old levels; Class B covers fairly common small-scale or light-use services and is the closest heir of the old Low baseline; Class C covers common enterprise services and is the closest heir of Moderate; and Class D, the high-impact tier, is not yet final — FedRAMP is building it in Phase 4. FedRAMP cautions that each class signals a level of assurance and is not merely a rebadged Low, Moderate, or High.
What replaced the Low, Moderate, and High impact levels?
FedRAMP 20x expresses authorization through Certification Classes, which carry the old levels' lineage rather than their names. Class B is the closest heir of Low and Class C of Moderate, while Class A is an additional entry tier and Class D, still in development, points toward High. FedRAMP itself cautions that classes indicate assurance level and are not one-for-one replacements for the old impact levels. Classes A, B, and C are finalized today.
What is FedRAMP 20x Class C?
Class C certifications cover common enterprise services likely to be used in systems across an entire agency. Class C is the closest heir of the old Moderate impact level and the class most enterprise SaaS ultimately needs, though entering at a lower class and climbing is the normal path. This is the class Anecdotes holds.
What is FedRAMP 20x Class A?
Class A is FedRAMP 20x's light entry tier, defined from both sides: for providers, it covers cloud services with mature security and compliance programs entering the federal marketplace; for agencies, it is adequate for pilots and negligible-risk use cases such as processing public information. It maps to no legacy impact level, and it is not the old "FedRAMP Ready" designation.
What is FedRAMP 20x Class B?
Class B certifications cover fairly common small-scale or light-use services that an entire agency is unlikely to rely on for important work. Class B is the closest heir of the old Low impact level.
What is FedRAMP 20x Class D?
Class D is FedRAMP 20x's high-impact tier, intended for the most sensitive federal systems. Its rules are not final: the FedRAMP program states that Class D will be developed during Phase 4, with a pilot estimated for late 2026 into early 2027.
Is Class D available yet, or still a pilot?
Not yet. Classes A, B, and C are finalized and available now, while Class D is still taking shape in Phase 4. FedRAMP estimates a Class D pilot for late 2026 into early 2027 and is explicit that the date is an estimate.
What is the FedRAMP 20x pilot?
The pilot is how 20x was built. Phase 1, which ran April through September 2025, proved that security outcomes could be validated automatically; Phase 2 added the Moderate requirements and tested them with provider cohorts, and Anecdotes was one of 13 participants in Phase 2 Cohort 2. Those outcomes are now formalized for Classes A through C, and a Class D pilot is estimated for late 2026 into early 2027 in Phase 4.
Who needs FedRAMP 20x?
Cloud service providers (CSPs) that sell, or want to sell, software to U.S. federal agencies. In practice that means the GRC and security teams inside those providers who own reaching and maintaining authorization.
Does FedRAMP 20x require an agency sponsor?
Not to begin. FedRAMP 20x created a certification path that does not depend on lining up a sponsoring agency first, which is how horizontal providers such as GRC tools, long unable to secure a single sponsor, finally got in. Agencies still authorize and rely on the services once they are certified.
Is FedRAMP 20x mandatory, and does it replace Rev5 completely?
FedRAMP 20x is the path forward for new authorizations, while existing Rev5 authorizations remain valid and providers are not forced to migrate overnight. The wind-down does have a date: no new Rev5 Certifications will be issued after June 11, 2027. For the transition specifics, see our post on the FedRAMP 20x transition.
What are the FedRAMP 20x requirements, in brief?
At a high level, 20x asks a provider to prove a set of Key Security Indicators (discrete security outcomes) with current, machine-readable evidence, and to keep that proof continuously validated rather than assembled once a year. The specific requirements live in our FedRAMP 20x KSI checklist.
What are Key Security Indicators (KSIs) in FedRAMP 20x?
KSIs are the discrete, testable security requirements FedRAMP 20x validates continuously: each states a measurable outcome, such as enforced phishing-resistant MFA, that is checked against machine-readable evidence. The full theme-by-theme reference lives in our FedRAMP 20x KSI checklist.
Can I reuse my ISO 27001 or SOC 2 evidence for FedRAMP 20x?
Much of it, yes. Control evidence collected for ISO 27001, SOC 2, and internal risk work maps to many 20x KSIs, and on a platform built for requirement-level cross-mapping it can support 20x without a separate collection effort. A mapping shows a relationship, not a finished control, so each KSI's specific bar still has to be met.
How does FedRAMP 20x handle continuous monitoring?
Continuous validation is the point of 20x. KSIs are checked against current, machine-readable evidence on an ongoing basis, so status reflects where a provider stands now rather than where it stood at its last annual review.
How do agencies and assessors see a 20x provider's status?
Through a machine-readable authorization package. On Anecdotes, agencies and independent assessors can pull current KSI status and the evidence beneath it directly through the Trust Center and API, rather than waiting on a static file.
Is Anecdotes FedRAMP 20x certified?
Yes. Anecdotes holds a FedRAMP 20x Moderate (Class C) certification, earned on its own platform, so its reading of the framework comes from having done the work, not from watching others do it.
How is FedRAMP 20x different from Rev5?
Rev5 authorized through periodic, document-based assessment; FedRAMP 20x authorizes through continuous, KSI-based validation and a path that needs no agency sponsor to begin. For the full comparison and the migration timeline, see our post on the FedRAMP 20x transition.
How long does FedRAMP 20x take?
How long FedRAMP 20x takes depends on your starting point and how much of your evidence is already automated, and an honest answer needs its own walkthrough. Our guide on how to get FedRAMP 20x certified covers the procedure and the factors that move the timeline.
What is FedRAMP, and how does 20x fit into it?
FedRAMP is the U.S. government's program for authorizing cloud services for federal use, so agencies do not each assess the same provider from scratch. FedRAMP 20x is the program's modernized generation, trading point-in-time paperwork for continuous, automated validation.
Key takeaways
- FedRAMP 20x is the modernized FedRAMP: continuous, machine-verifiable validation built on Key Security Indicators (KSIs), in place of Rev5's document-heavy, once-a-year review.
- Authorization is organized into Certification Classes A–D, a lineage from the old impact levels rather than a rename: Class B is the closest heir of Low, Class C of Moderate (the class most enterprise SaaS ultimately needs, and the one Anecdotes holds), Class A is a new entry tier and the normal place to start the climb, and Class D (High) is still being developed in Phase 4.
- KSIs are discrete, testable security outcomes proven with current evidence: requirement-level, continuously evidenced compliance instead of point-in-time narratives.
- 20x opened a path to certification without an agency sponsor up front, which let in horizontal providers that previously could not find one.
- The evidence you already collect for other frameworks can be reused toward 20x, as long as you remember that a mapping shows a relationship, not a finished control.





